Error when trying to use online accounts for Fedora login

Happens with the Nextcloud account and the fedora account. Tried googling, but only found answers pertinent to kerberos.

Yes, the Fedora account is the FAS account (the one used on this forum) and it uses kerberos.

3 Likes

For the Fedora account, try: <FAS>@FEDORAPROJECT.ORG. That’s required when we do kinit on the terminal—apparently domain names need to be in capitals for some implementation reason there. Could apply to the GUI too.

Not sure about the nextcloud bit: what error do you see there? Same one?

3 Likes

Thanks for the reply. I have now tried both with uppercase and lowercase, with and without the @. It’s as if it doesn’t even load - I just get the error instantly.
As for the Nextcloud account, it loads but I get ‘authentication error’ no matter what.

I used to have both set up and configured in my online accounts but I stumbled across the exclamation mark next to them yesterday. I tried re-signing in but I got the errors, so I decided to remove them and try adding the accounts again and I got the same errors that I get now.

I’m starting to suspect that some GNOME update might have broken it.

2 Likes

That is possible yeh. I haven’t used either recently so we’ll need to wait for someone that does to confirm the issue. Could you have a look at the journal to see if there are any warning/error messages related to this?

In the meantime, for Fedora, you should be able to sign in using the command line (I think it does the same thing).:

kinit <FAS>@FEDORAPROJECT.ORG

That’ll also show up in your Online accounts.

EDIT:

Are you seeing the same error for NextCloud and Fedora accounts? The Fedora account sounds like a Kerberos related error, which should be different from the NextCloud one.

1 Like
$~ kinit [MYUSER]@FEDORAPROJECT.ORG
$~ kinit: Connection refused while getting default ccache

I ran journalctl --no-pager but nothing relevant shows up.

No, they’re different.

1 Like

So, this seems to be a kerberos related error. Is your /tmp partition full? That’s where the default cache is created and there are number of posts on the web where this being full causes issues.

Also worth trying:

kinit -V ...

to see if the verbose input provides hints.

What’s the nextcloud error? We’ll need to debug that separately.

1 Like

Hmmm… I don’t know :thinking: How do I check this? I tried googling a little, but many of the threads were old, while others warned about cleaning it.

$~ kinit -V ...
$~ kinit: Connection refused while getting default ccache

93845ea91b713e9e145935d67135987aa5f7bcd0.png

And I’m 1000% sure I have all the parameters correct.

Mega edit:

I’ve confirmed with the Fedora Infrastructure team. Anyone with a Fedora account on https://admin.fedoraproject.org/accounts/ should be able to use this. No additional configuration is necessary.

when using kinit, one has to use:

kinit <FAS username>@FEDORAPROJECT.ORG

(yes, it needs to be caps).

The password here should be the password that you use to login to https://admin.fedoraproject.org/accounts/ (and not your local laptop login password).

1 Like

Appreciate the help and time you take, Ankur - I’d buy you a coffee!
I have to be honest, though: it isn’t of vital importance - I just thought it was odd that none of these are working when they used to perfectly fine. That being said, I have tried again now, using both uppercase and lowercase etc. and nothing works ;/ Thanks :+1:

1 Like

Uh, then that’s something not related to Fedora infra then. :thinking:
Do you want to open a different issue for NextCloud? We can tweak the title here to focus on the kerberos bit.

1 Like

Sure, let’s go :grinning_face_with_smiling_eyes:

1 Like

Posting from my laptop now. Seems to work here… :roll_eyes:
fabf99b7c2cccdf10f67c9c91a459d983fcd903e.png

1 Like

Hrm, same network, same configuration? Maybe just reboot and try on the other machine too? :stuck_out_tongue:

Did you open a new topic for the NextCloud issue? I’m sure there’ll be folks who use it and will be able to help.

1 Like

Come to think of it, I think the problem with Nextcloud might be that I activated 2FA on my account :sweat_smile:

I did KRB5_TRACE=/dev/stderr strace -f klist and under is the output of it:

execve("/usr/bin/klist", ["klist"], 0x7ffd0e92b1c8 /* 74 vars */) = 0
brk(NULL)                               = 0x55987d06b000
arch_prctl(0x3001 /* ARCH_??? */, 0x7ffd23e055f0) = -1 EINVAL (Invalid argument)
access("/etc/ld.so.preload", R_OK)      = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=181359, ...}) = 0
mmap(NULL, 181359, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f2365bcd000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libkrb5.so.3", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@X\2\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=881856, ...}) = 0
mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2365bcb000
mmap(NULL, 873616, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f2365af5000
mprotect(0x7f2365b18000, 667648, PROT_NONE) = 0
mmap(0x7f2365b18000, 409600, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x23000) = 0x7f2365b18000
mmap(0x7f2365b7c000, 253952, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x87000) = 0x7f2365b7c000
mmap(0x7f2365bbb000, 65536, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xc5000) = 0x7f2365bbb000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libk5crypto.so.3", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000W\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=94464, ...}) = 0
mmap(NULL, 94272, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f2365add000
mmap(0x7f2365ae2000, 49152, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x5000) = 0x7f2365ae2000
mmap(0x7f2365aee000, 16384, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x11000) = 0x7f2365aee000
mmap(0x7f2365af2000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x14000) = 0x7f2365af2000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libcom_err.so.2", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240\"\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=19720, ...}) = 0
mmap(NULL, 20640, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f2365ad7000
mmap(0x7f2365ad9000, 4096, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7f2365ad9000
mmap(0x7f2365ada000, 4096, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3000) = 0x7f2365ada000
mmap(0x7f2365adb000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3000) = 0x7f2365adb000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libkrb5support.so.0", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\240G\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=65888, ...}) = 0
mmap(NULL, 66192, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f2365ac6000
mmap(0x7f2365aca000, 32768, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f2365aca000
mmap(0x7f2365ad2000, 12288, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xc000) = 0x7f2365ad2000
mmap(0x7f2365ad5000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xe000) = 0x7f2365ad5000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libc.so.6", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0 \203\2\0\0\0\0\0"..., 832) = 832
pread64(3, "\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0"..., 784, 64) = 784
pread64(3, "\4\0\0\0\20\0\0\0\5\0\0\0GNU\0\2\0\0\300\4\0\0\0\3\0\0\0\0\0\0\0", 32, 848) = 32
pread64(3, "\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\241jd\33\245D\344l\205\274\324\21\366\271\374\351"..., 68, 880) = 68
fstat(3, {st_mode=S_IFREG|0755, st_size=3222048, ...}) = 0
pread64(3, "\6\0\0\0\4\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0@\0\0\0\0\0\0\0"..., 784, 64) = 784
mmap(NULL, 1876640, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f23658fb000
mprotect(0x7f2365921000, 1683456, PROT_NONE) = 0
mmap(0x7f2365921000, 1372160, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x26000) = 0x7f2365921000
mmap(0x7f2365a70000, 307200, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x175000) = 0x7f2365a70000
mmap(0x7f2365abc000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1c0000) = 0x7f2365abc000
mmap(0x7f2365ac2000, 12960, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f2365ac2000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libkeyutils.so.1", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260$\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=24432, ...}) = 0
mmap(NULL, 24584, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f23658f4000
mmap(0x7f23658f6000, 8192, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7f23658f6000
mmap(0x7f23658f8000, 4096, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f23658f8000
mmap(0x7f23658f9000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f23658f9000
mmap(0x7f23658fa000, 8, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f23658fa000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libcrypto.so.1.1", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\300\7\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=3092424, ...}) = 0
mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f23658f2000
mmap(NULL, 3067688, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f2365605000
mmap(0x7f236567f000, 1761280, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7a000) = 0x7f236567f000
mmap(0x7f236582d000, 593920, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x228000) = 0x7f236582d000
mmap(0x7f23658be000, 196608, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2b8000) = 0x7f23658be000
mmap(0x7f23658ee000, 16168, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f23658ee000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libresolv.so.2", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000G\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=130320, ...}) = 0
mmap(NULL, 104608, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f23655eb000
mprotect(0x7f23655ef000, 73728, PROT_NONE) = 0
mmap(0x7f23655ef000, 57344, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f23655ef000
mmap(0x7f23655fd000, 12288, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x12000) = 0x7f23655fd000
mmap(0x7f2365601000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x15000) = 0x7f2365601000
mmap(0x7f2365603000, 6304, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f2365603000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libpthread.so.0", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@\201\0\0\0\0\0\0"..., 832) = 832
pread64(3, "\4\0\0\0\24\0\0\0\3\0\0\0GNU\0\34\205\3419\216--t\307r]2\212\344\\\200"..., 68, 824) = 68
fstat(3, {st_mode=S_IFREG|0755, st_size=304664, ...}) = 0
mmap(NULL, 135600, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f23655c9000
mmap(0x7f23655d0000, 65536, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x7f23655d0000
mmap(0x7f23655e0000, 20480, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x17000) = 0x7f23655e0000
mmap(0x7f23655e5000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1b000) = 0x7f23655e5000
mmap(0x7f23655e7000, 12720, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f23655e7000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libselinux.so.1", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P\213\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=175960, ...}) = 0
mmap(NULL, 181736, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f236559c000
mmap(0x7f23655a3000, 106496, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x7000) = 0x7f23655a3000
mmap(0x7f23655bd000, 32768, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x21000) = 0x7f23655bd000
mmap(0x7f23655c5000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x28000) = 0x7f23655c5000
mmap(0x7f23655c7000, 5608, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f23655c7000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libdl.so.2", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0p\"\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=37240, ...}) = 0
mmap(NULL, 24688, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f2365595000
mmap(0x7f2365597000, 8192, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7f2365597000
mmap(0x7f2365599000, 4096, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f2365599000
mmap(0x7f236559a000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x7f236559a000
mmap(0x7f236559b000, 112, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f236559b000
close(3)                                = 0
openat(AT_FDCWD, "/lib64/libz.so.1", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\3605\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=103104, ...}) = 0
mmap(NULL, 102408, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f236557b000
mprotect(0x7f236557e000, 86016, PROT_NONE) = 0
mmap(0x7f236557e000, 57344, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x3000) = 0x7f236557e000
mmap(0x7f236558c000, 24576, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x11000) = 0x7f236558c000
mmap(0x7f2365593000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x17000) = 0x7f2365593000
mmap(0x7f2365594000, 8, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f2365594000
close(3)                                = 0
mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2365579000
openat(AT_FDCWD, "/lib64/libpcre2-8.so.0", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260$\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=618648, ...}) = 0
mmap(NULL, 614960, PROT_READ, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f23654e2000
mmap(0x7f23654e4000, 434176, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x7f23654e4000
mmap(0x7f236554e000, 167936, PROT_READ, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x6c000) = 0x7f236554e000
mmap(0x7f2365577000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x94000) = 0x7f2365577000
close(3)                                = 0
mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f23654e0000
arch_prctl(ARCH_SET_FS, 0x7f23654e0c80) = 0
mprotect(0x7f2365abc000, 12288, PROT_READ) = 0
mprotect(0x7f23655e5000, 4096, PROT_READ) = 0
mprotect(0x7f2365577000, 4096, PROT_READ) = 0
mprotect(0x7f2365593000, 4096, PROT_READ) = 0
mprotect(0x7f236559a000, 4096, PROT_READ) = 0
mprotect(0x7f23655c5000, 4096, PROT_READ) = 0
mprotect(0x7f2365601000, 4096, PROT_READ) = 0
mprotect(0x7f23658be000, 180224, PROT_READ) = 0
mprotect(0x7f23658f9000, 4096, PROT_READ) = 0
mprotect(0x7f2365ad5000, 4096, PROT_READ) = 0
mprotect(0x7f2365adb000, 4096, PROT_READ) = 0
mprotect(0x7f2365af2000, 8192, PROT_READ) = 0
mprotect(0x7f2365bbb000, 57344, PROT_READ) = 0
mprotect(0x55987c144000, 4096, PROT_READ) = 0
mprotect(0x7f2365c25000, 4096, PROT_READ) = 0
munmap(0x7f2365bcd000, 181359)          = 0
set_tid_address(0x7f23654e0f50)         = 24114
set_robust_list(0x7f23654e0f60, 24)     = 0
rt_sigaction(SIGRTMIN, {sa_handler=0x7f23655d0ba0, sa_mask=[], sa_flags=SA_RESTORER|SA_SIGINFO, sa_restorer=0x7f23655dd1e0}, NULL, 8) = 0
rt_sigaction(SIGRT_1, {sa_handler=0x7f23655d0c40, sa_mask=[], sa_flags=SA_RESTORER|SA_RESTART|SA_SIGINFO, sa_restorer=0x7f23655dd1e0}, NULL, 8) = 0
rt_sigprocmask(SIG_UNBLOCK, [RTMIN RT_1], NULL, 8) = 0
prlimit64(0, RLIMIT_STACK, NULL, {rlim_cur=8192*1024, rlim_max=RLIM64_INFINITY}) = 0
statfs("/sys/fs/selinux", {f_type=SELINUX_MAGIC, f_bsize=4096, f_blocks=0, f_bfree=0, f_bavail=0, f_files=0, f_ffree=0, f_fsid={val=[0, 0]}, f_namelen=255, f_frsize=4096, f_flags=ST_VALID|ST_NOSUID|ST_NOEXEC|ST_RELATIME}) = 0
statfs("/sys/fs/selinux", {f_type=SELINUX_MAGIC, f_bsize=4096, f_blocks=0, f_bfree=0, f_bavail=0, f_files=0, f_ffree=0, f_fsid={val=[0, 0]}, f_namelen=255, f_frsize=4096, f_flags=ST_VALID|ST_NOSUID|ST_NOEXEC|ST_RELATIME}) = 0
brk(NULL)                               = 0x55987d06b000
brk(0x55987d08c000)                     = 0x55987d08c000
access("/etc/selinux/config", F_OK)     = 0
openat(AT_FDCWD, "/proc/sys/crypto/fips_enabled", O_RDONLY) = 3
read(3, "0\n", 2)                       = 2
close(3)                                = 0
access("/etc/system-fips", F_OK)        = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/lib/locale/locale-archive", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=223542144, ...}) = 0
mmap(NULL, 223542144, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f2357fb0000
close(3)                                = 0
openat(AT_FDCWD, "/etc/localtime", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=2228, ...}) = 0
fstat(3, {st_mode=S_IFREG|0644, st_size=2228, ...}) = 0
read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\7\0\0\0\7\0\0\0\0"..., 4096) = 2228
lseek(3, -1410, SEEK_CUR)               = 818
read(3, "TZif2\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\7\0\0\0\7\0\0\0\0"..., 4096) = 1410
close(3)                                = 0
futex(0x7f2365ad6288, FUTEX_WAKE_PRIVATE, 2147483647) = 0
futex(0x7f2365ad60d0, FUTEX_WAKE_PRIVATE, 2147483647) = 0
futex(0x7f2365bc9cf0, FUTEX_WAKE_PRIVATE, 2147483647) = 0
futex(0x7f2365bca150, FUTEX_WAKE_PRIVATE, 2147483647) = 0
stat("/etc/krb5.conf", {st_mode=S_IFREG|0644, st_size=880, ...}) = 0
openat(AT_FDCWD, "/etc/krb5.conf", O_RDONLY) = 3
fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
fstat(3, {st_mode=S_IFREG|0644, st_size=880, ...}) = 0
read(3, "# To opt out of the system crypt"..., 4096) = 880
openat(AT_FDCWD, "/etc/krb5.conf.d/", O_RDONLY|O_NONBLOCK|O_CLOEXEC|O_DIRECTORY) = 4
fstat(4, {st_mode=S_IFDIR|0755, st_size=66, ...}) = 0
getdents64(4, 0x55987d06fc80 /* 4 entries */, 32768) = 128
getdents64(4, 0x55987d06fc80 /* 0 entries */, 32768) = 0
close(4)                                = 0
openat(AT_FDCWD, "/etc/krb5.conf.d//crypto-policies", O_RDONLY) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=179, ...}) = 0
read(4, "[libdefaults]\npermitted_enctypes"..., 4096) = 179
read(4, "", 4096)                       = 0
close(4)                                = 0
openat(AT_FDCWD, "/etc/krb5.conf.d//kcm_default_ccache", O_RDONLY) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=494, ...}) = 0
read(4, "# This file should normally be i"..., 4096) = 494
read(4, "", 4096)                       = 0
close(4)                                = 0
read(3, "", 4096)                       = 0
close(3)                                = 0
futex(0x7f2365ad6000, FUTEX_WAKE_PRIVATE, 2147483647) = 0
futex(0x7f23655c72e8, FUTEX_WAKE_PRIVATE, 2147483647) = 0
openat(AT_FDCWD, "/proc/thread-self/attr/fscreate", O_RDONLY|O_CLOEXEC) = 3
read(3, "", 4095)                       = 0
close(3)                                = 0
openat(AT_FDCWD, "/etc/selinux/config", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=548, ...}) = 0
read(3, "\n# This file controls the state "..., 4096) = 548
read(3, "", 4096)                       = 0
close(3)                                = 0
futex(0x7f23655c8540, FUTEX_WAKE_PRIVATE, 2147483647) = 0
stat("/etc/selinux/targeted/contexts/files/file_contexts", {st_mode=S_IFREG|0644, st_size=407918, ...}) = 0
openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.subs_dist", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=625, ...}) = 0
fstat(3, {st_mode=S_IFREG|0644, st_size=625, ...}) = 0
read(3, "/run /var/run\n/run/lock /var/loc"..., 4096) = 625
read(3, "", 4096)                       = 0
close(3)                                = 0
openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.subs", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=0, ...}) = 0
fstat(3, {st_mode=S_IFREG|0644, st_size=0, ...}) = 0
read(3, "", 4096)                       = 0
close(3)                                = 0
stat("/etc/selinux/targeted/contexts/files/file_contexts", {st_mode=S_IFREG|0644, st_size=407918, ...}) = 0
stat("/etc/selinux/targeted/contexts/files/file_contexts.bin", {st_mode=S_IFREG|0644, st_size=574738, ...}) = 0
openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.bin", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=574738, ...}) = 0
read(3, "\212\377|\371\5\0\0\0\20\0\0\00010.36 2020-12-04\6\0\0\0"..., 4096) = 4096
lseek(3, 0, SEEK_SET)                   = 0
mmap(NULL, 574738, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f2357f23000
brk(NULL)                               = 0x55987d08c000
brk(0x55987d0c4000)                     = 0x55987d0c4000
brk(NULL)                               = 0x55987d0c4000
brk(0x55987d0e5000)                     = 0x55987d0e5000
mmap(NULL, 491520, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2357eab000
mremap(0x7f2357eab000, 491520, 983040, MREMAP_MAYMOVE) = 0x7f2357dbb000
close(3)                                = 0
stat("/etc/selinux/targeted/contexts/files/file_contexts.homedirs", {st_mode=S_IFREG|0644, st_size=14009, ...}) = 0
stat("/etc/selinux/targeted/contexts/files/file_contexts.homedirs.bin", {st_mode=S_IFREG|0644, st_size=19261, ...}) = 0
openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.homedirs.bin", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=19261, ...}) = 0
read(3, "\212\377|\371\5\0\0\0\20\0\0\00010.36 2020-12-04\6\0\0\0"..., 4096) = 4096
lseek(3, 0, SEEK_SET)                   = 0
mmap(NULL, 19261, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f2365bf5000
close(3)                                = 0
stat("/etc/selinux/targeted/contexts/files/file_contexts.local", {st_mode=S_IFREG|0644, st_size=0, ...}) = 0
stat("/etc/selinux/targeted/contexts/files/file_contexts.local.bin", 0x7ffd23dff090) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/etc/selinux/targeted/contexts/files/file_contexts.local", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=0, ...}) = 0
read(3, "", 4096)                       = 0
lseek(3, 0, SEEK_SET)                   = 0
read(3, "", 4096)                       = 0
close(3)                                = 0
mmap(NULL, 798720, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f2357cf8000
munmap(0x7f2357dbb000, 983040)          = 0
brk(NULL)                               = 0x55987d0e5000
brk(0x55987d106000)                     = 0x55987d106000
access("/var/run/setrans/.setrans-unix", F_OK) = -1 ENOENT (No such file or directory)
futex(0x7f23655c85d0, FUTEX_WAKE_PRIVATE, 2147483647) = 0
openat(AT_FDCWD, "/proc/thread-self/attr/current", O_RDONLY|O_CLOEXEC) = 3
read(3, "unconfined_u:unconfined_r:unconf"..., 4095) = 54
close(3)                                = 0
openat(AT_FDCWD, "/proc/thread-self/attr/fscreate", O_RDWR|O_CLOEXEC) = 3
write(3, "unconfined_u:object_r:device_t:s"..., 34) = 34
close(3)                                = 0
openat(AT_FDCWD, "/dev/stderr", O_WRONLY|O_CREAT|O_APPEND, 0600) = 3
openat(AT_FDCWD, "/proc/thread-self/attr/fscreate", O_RDWR|O_CLOEXEC) = 4
write(4, NULL, 0)                       = 0
close(4)                                = 0
munmap(0x7f2357cf8000, 798720)          = 0
munmap(0x7f2365bf5000, 19261)           = 0
munmap(0x7f2357f23000, 574738)          = 0
getpid()                                = 24114
socket(AF_UNIX, SOCK_STREAM, 0)         = 4
connect(4, {sa_family=AF_UNIX, sun_path="/var/run/.heim_org.h5l.kcm-socket"}, 110) = -1 ECONNREFUSED (Connection refused)
close(4)                                = 0
openat(AT_FDCWD, "/usr/share/locale/locale.alias", O_RDONLY|O_CLOEXEC) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=2998, ...}) = 0
read(4, "# Locale name alias data base.\n#"..., 4096) = 2998
read(4, "", 4096)                       = 0
close(4)                                = 0
openat(AT_FDCWD, "/usr/share/locale/en_US.UTF-8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en_US.utf8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en_US/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=369, ...}) = 0
mmap(NULL, 369, PROT_READ, MAP_PRIVATE, 4, 0) = 0x7f2365bf9000
close(4)                                = 0
openat(AT_FDCWD, "/usr/share/locale/en.UTF-8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en.utf8/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en/LC_MESSAGES/mit-krb5.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en_US.UTF-8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en_US.utf8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en_US/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en.UTF-8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en.utf8/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
openat(AT_FDCWD, "/usr/share/locale/en/LC_MESSAGES/libc.mo", O_RDONLY) = -1 ENOENT (No such file or directory)
write(2, "klist: Connection refused ", 26klist: Connection refused ) = 26
write(2, "while resolving ccache", 22while resolving ccache)  = 22
write(2, "\n", 1
)                       = 1
exit_group(1)                           = ?
+++ exited with 1 +++

Unfortunately, I don’t know what to look for.

1 Like

This seems to be the bit. Now, the default ccache, from /etc/krb5.conf seems to be:

default_ccache_name = KEYRING:persistent:%{uid}

I can only find this about the KEYRING bit:

https://web.mit.edu/kerberos/www/krb5-latest/doc/basic/ccache_def.html?highlight=keyring

This suggests it relies on SSSD:

https://community.cloudera.com/t5/Support-Questions/Kerberos-Cache-in-IPA-RedHat-IDM-KEYRING-SOLVED/td-p/108373

Do you have the SSSD service running?

sudo systemctl status sssd.service

Let’s also look at your versions:

rpm -qa krb5\* sssd\*

So, it seems the issue is related to it now being able to connect to the KEYRING ccache. Whether it’s something on your system or a bug is unclear to me. If we don’t get to the bottom of it in a bit, I’d suggest filing a bug so that someone who knows the details behind how this works can take a look?

1 Like

Ah, lol. :laughing:

1 Like
sssd.service - System Security Services Daemon
     Loaded: loaded (/usr/lib/systemd/system/sssd.service; enabled; vendor preset: enabled)
     Active: failed (Result: exit-code) since Mon 2021-01-25 14:51:43 CET; 805ms ago
    Process: 118767 ExecStart=/usr/sbin/sssd -i ${DEBUG_LOGGER} (code=exited, status=7)
   Main PID: 118767 (code=exited, status=7)
        CPU: 3ms

jan. 25 14:51:43 fedora-desk systemd[1]: sssd.service: Scheduled restart job, restart counter is at 5.
jan. 25 14:51:43 fedora-desk systemd[1]: Stopped System Security Services Daemon.
jan. 25 14:51:43 fedora-desk systemd[1]: sssd.service: Start request repeated too quickly.
jan. 25 14:51:43 fedora-desk systemd[1]: sssd.service: Failed with result 'exit-code'.
jan. 25 14:51:43 fedora-desk systemd[1]: Failed to start System Security Services Daemon.

Running sudo systemctl start sssd.service gives me:

Job for sssd.service failed because the control process exited with error code.
See "systemctl status sssd.service" and "journalctl -xe" for details.

And journalctl -xe gives me:

jan. 25 14:51:42 fedora-desk audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 ms>
jan. 25 14:51:43 fedora-desk systemd[1]: sssd.service: Scheduled restart job, restart counter is at 5.
░░ Subject: Automatic restarting of a unit has been scheduled
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ Automatic restarting of the unit sssd.service has been scheduled, as the result for
░░ the configured Restart= setting for the unit.
jan. 25 14:51:43 fedora-desk systemd[1]: Stopped System Security Services Daemon.
░░ Subject: A stop job for unit sssd.service has finished
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ A stop job for unit sssd.service has finished.
░░ 
░░ The job identifier is 15173 and the job result is done.
jan. 25 14:51:43 fedora-desk audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 ms>
jan. 25 14:51:43 fedora-desk audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg>
jan. 25 14:51:43 fedora-desk systemd[1]: sssd.service: Start request repeated too quickly.
jan. 25 14:51:43 fedora-desk systemd[1]: sssd.service: Failed with result 'exit-code'.
░░ Subject: Unit failed
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ The unit sssd.service has entered the 'failed' state with result 'exit-code'.
jan. 25 14:51:43 fedora-desk systemd[1]: Failed to start System Security Services Daemon.
░░ Subject: A start job for unit sssd.service has failed
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ A start job for unit sssd.service has finished with a failure.
░░ 
░░ The job identifier is 15173 and the job result is failed.
jan. 25 14:51:43 fedora-desk audit[118768]: USER_ACCT pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined>
jan. 25 14:51:43 fedora-desk audit[118768]: USER_CMD pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined_>
jan. 25 14:51:43 fedora-desk sudo[118768]:     zeno : TTY=pts/0 ; PWD=/home/zeno ; USER=root ; COMMAND=/usr/bin/systemctl status ss>
jan. 25 14:51:43 fedora-desk audit[118768]: CRED_REFR pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined>
jan. 25 14:51:43 fedora-desk sudo[118768]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)
jan. 25 14:51:43 fedora-desk audit[118768]: USER_START pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfine>
jan. 25 14:51:43 fedora-desk sudo[118768]: pam_unix(sudo:session): session closed for user root
jan. 25 14:51:43 fedora-desk audit[118768]: USER_END pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined_>
jan. 25 14:51:43 fedora-desk audit[118768]: CRED_DISP pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined>
...skipping...
jan. 25 14:51:42 fedora-desk audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 ms>
jan. 25 14:51:43 fedora-desk systemd[1]: sssd.service: Scheduled restart job, restart counter is at 5.
░░ Subject: Automatic restarting of a unit has been scheduled
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ Automatic restarting of the unit sssd.service has been scheduled, as the result for
░░ the configured Restart= setting for the unit.
jan. 25 14:51:43 fedora-desk systemd[1]: Stopped System Security Services Daemon.
░░ Subject: A stop job for unit sssd.service has finished
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ A stop job for unit sssd.service has finished.
░░ 
░░ The job identifier is 15173 and the job result is done.
jan. 25 14:51:43 fedora-desk audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 ms>
jan. 25 14:51:43 fedora-desk audit[1]: SERVICE_STOP pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg>
jan. 25 14:51:43 fedora-desk systemd[1]: sssd.service: Start request repeated too quickly.
jan. 25 14:51:43 fedora-desk systemd[1]: sssd.service: Failed with result 'exit-code'.
░░ Subject: Unit failed
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ The unit sssd.service has entered the 'failed' state with result 'exit-code'.
jan. 25 14:51:43 fedora-desk systemd[1]: Failed to start System Security Services Daemon.
░░ Subject: A start job for unit sssd.service has failed
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ A start job for unit sssd.service has finished with a failure.
░░ 
░░ The job identifier is 15173 and the job result is failed.
jan. 25 14:51:43 fedora-desk audit[118768]: USER_ACCT pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined>
jan. 25 14:51:43 fedora-desk audit[118768]: USER_CMD pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined_>
jan. 25 14:51:43 fedora-desk sudo[118768]:     zeno : TTY=pts/0 ; PWD=/home/zeno ; USER=root ; COMMAND=/usr/bin/systemctl status ss>
jan. 25 14:51:43 fedora-desk audit[118768]: CRED_REFR pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined>
jan. 25 14:51:43 fedora-desk sudo[118768]: pam_unix(sudo:session): session opened for user root(uid=0) by (uid=1000)
jan. 25 14:51:43 fedora-desk audit[118768]: USER_START pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfine>
jan. 25 14:51:43 fedora-desk sudo[118768]: pam_unix(sudo:session): session closed for user root
jan. 25 14:51:43 fedora-desk audit[118768]: USER_END pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined_>
jan. 25 14:51:43 fedora-desk audit[118768]: CRED_DISP pid=118768 uid=1000 auid=1000 ses=3 subj=unconfined_u:unconfined_r:unconfined>

Finally, rpm -qa krb5\* sssd\* gives me:

krb5-libs-1.18.2-29.fc33.x86_64
sssd-nfs-idmap-2.4.0-4.fc33.x86_64
sssd-client-2.4.0-4.fc33.x86_64
sssd-common-2.4.0-4.fc33.x86_64
sssd-krb5-common-2.4.0-4.fc33.x86_64
sssd-common-pac-2.4.0-4.fc33.x86_64
sssd-ad-2.4.0-4.fc33.x86_64
sssd-ipa-2.4.0-4.fc33.x86_64
sssd-krb5-2.4.0-4.fc33.x86_64
sssd-ldap-2.4.0-4.fc33.x86_64
sssd-proxy-2.4.0-4.fc33.x86_64
sssd-2.4.0-4.fc33.x86_64
sssd-kcm-2.4.0-4.fc33.x86_64
krb5-libs-1.18.2-29.fc33.i686
krb5-devel-1.18.2-29.fc33.x86_64
krb5-pkinit-1.18.2-29.fc33.x86_64
krb5-workstation-1.18.2-29.fc33.x86_64
1 Like

Yes, of course. Sorry, this has dragged a lot and I don’t want to waste your time :sweat: You’ve been most helpful and I really appreciate it!

1 Like

So this could certainly be causing it, since the docs suggest that sssd needs to be active for krb5 services to run.

Here are my package versions. So that looks good (you have more than what I do, but that shouldn’t make a difference):

$ rpm -qa krb5\* sssd\*
krb5-libs-1.18.2-29.fc33.x86_64
krb5-workstation-1.18.2-29.fc33.x86_64
sssd-nfs-idmap-2.4.0-4.fc33.x86_64
sssd-client-2.4.0-4.fc33.x86_64
sssd-common-2.4.0-4.fc33.x86_64
sssd-krb5-common-2.4.0-4.fc33.x86_64
sssd-common-pac-2.4.0-4.fc33.x86_64
sssd-ad-2.4.0-4.fc33.x86_64
sssd-krb5-2.4.0-4.fc33.x86_64
sssd-ldap-2.4.0-4.fc33.x86_64
sssd-proxy-2.4.0-4.fc33.x86_64
sssd-ipa-2.4.0-4.fc33.x86_64
sssd-2.4.0-4.fc33.x86_64
sssd-kcm-2.4.0-4.fc33.x86_64

I’m looking at how we can find out why sssd isn’t starting up correctly. This seems to have some ideas. Worth a try?

https://proneon267.github.io/2020/02/05/sssd-service-failed.html

Nah, no worries. Some of these issues require more digging in than others. I don’t know much about krb or sssd, so this is just me poking about and reading up here and there :laughing:

3 Likes